Security

Security designed around customer isolation.

REFRACT is built as a multi-tenant platform: every customer organization operates its own workspace, kept separate from every other customer's and from this public website. We're a young, focused product — we'd rather tell you plainly what's confirmed today than dress it up.

Overview

What's confirmed, and what isn't yet

Every statement on this page is checked against our internal security-claims register before publication. Where a control is confirmed, it's labeled Verified. Where a topic is real but not yet formally confirmed for public disclosure, it's labeled Documentation in progress — never dressed up with vague language like 'enterprise-grade' or 'bank-level' to fill the gap.

Want the fuller picture of how REFRACT works day to day? See the product overview or the feature list.

Verified

Tenant and workspace isolation

Each customer organization is served from its own dedicated subdomain — for example, an organization's workspace lives at [businessname].refractsoftware.com — separate from every other organization's workspace and from this public marketing site. This subdomain-per-organization deployment model is REFRACT's confirmed architecture.

northline-hvac.refractsoftware.com
Workspace A — separate from every other organization's workspace
crestpoint-mechanical.refractsoftware.com
Workspace B — separate from every other organization's workspace
vantage-industrial.refractsoftware.com
Workspace C — separate from every other organization's workspace

Illustrative example subdomains — not real REFRACT customer organizations.

We're formalizing public documentation of the deeper isolation mechanics behind each workspace (for example, how data stores are separated) and will publish that once it's ready to state precisely. If you need those details now for a security review, contact us directly — we're glad to walk through it.

Verified

This website holds no customer data

This public marketing site (refractsoftware.com) is a separate, static/marketing surface with no customer login, authentication, or session logic of any kind, and it holds no tenant or customer data. It is not part of the REFRACT application your team uses day to day — that lives entirely at your organization's own subdomain, in a separate application.

Transparency

Security topics we're still formalizing

These are the topics buyers ask about most. We're not going to answer them with plausible-sounding language we can't back up — where we don't have a confirmed, publishable answer yet, we say so, and route you to a real person instead.

Authentication

Documentation in progress

How users sign in and how sessions are managed isn't yet publicly documented. Ask us directly for an evaluation.

Roles & permissions

Documentation in progress

How access is scoped by role within an organization isn't yet publicly documented.

Transport & data protection

Documentation in progress

How data is protected in transit and at rest isn't yet publicly documented — we won't guess at a standard we haven't confirmed.

Infrastructure

Documentation in progress

Hosting, network, and environment-level protections aren't yet publicly documented.

Backups & recovery

Documentation in progress

Backup frequency, retention, and recovery process aren't yet publicly documented.

Secure development

Documentation in progress

Code review, dependency management, and release practices aren't yet publicly documented.

Vulnerability management

Documentation in progress

How security reports are triaged and handled isn't yet publicly documented.

Evaluating REFRACT for a security review and need one of these answered now? Contact REFRACT — a specific question is easier for us to answer precisely than a general page ever could be.

FAQ

Security questions we hear most

Is customer data shared between organizations?

Each customer organization operates its own workspace, served from its own dedicated subdomain, separate from every other organization's workspace. The specific mechanism behind that separation (for example, how data stores are isolated) isn't yet publicly documented — contact us if you need that confirmed for a security review.

Does each customer use a separate database?

That level of detail isn't yet publicly documented. What we can confirm today is the subdomain-per-organization workspace model described above. Contact us directly if you need this confirmed for procurement or a security review.

How are users authenticated?

Not yet publicly documented — reach out and we'll walk you through it directly.

Does REFRACT use HTTPS?

Specific transport-security details haven't been published yet. Contact us with any requirements from your evaluation and we'll answer directly.

How are user permissions handled?

Not yet publicly documented — contact us directly with questions about your evaluation.

Does this website require a login?

No. This is a public marketing site with no customer login, authentication, or session logic, and it holds no tenant or customer data. Your organization's REFRACT workspace is a separate application at your own dedicated subdomain.

Does REFRACT hold SOC 2 or ISO 27001 certification?

No. REFRACT does not currently hold SOC 2, ISO 27001, or any other third-party security certification. If that's needed for your procurement process, contact us to discuss timeline and options.

Where can I send a security question?

Through our Contact page — describe your question there and we'll route it appropriately. We don't yet have a dedicated security email address to publish here.

Security

Have a security question we haven't answered here?

Tell us what you're evaluating and we'll give you a direct, specific answer.